Data Breach, News Events, Risk Analysis/Risk Management

Sutter Health Breach Update

This past week, Sutter Health released a statement stating that they are notifying 2,582 patients that personal information was included in billing documents a former employee emailed to their personal account without authorization. For all but two of the affected patients, no Social Security numbers, financial information or driver’s license data were included.

Despite the incident occurring on April 23, 2013, the breach was only discovered “during a thorough review of the former employee’s email activity and computer access.” The internal investigation began on August 27, 2015, more than two years after the incident. What stands out in this instance was the inability for Sutter Health to discover, mitigate, and remediate this incident within a reasonable timeframe. When it comes to HIPAA, breaches must be reported to HHS and the individuals affected without unreasonable delay and in no case later than 60 days following discovery of a breach or when it reasonably should have been known that a breach occurred.

The last point is key and clearly indicates the need for tools that allow organizations to better understand when PHI or other types of sensitive data leave their network. The best option to track and stop data from leaving your network is a Data Loss Prevention (DLP) solution. In this incident, the third large data breach involving Sutter Health, they have found “no evidence that any of the patient information was used or disclosed to others.” Since the data was sent to a personal email account, it is unlikely, truly impossible, that Sutter Health can determine with 100% certainty that the patient information was not disclosed inappropriately and this is reflected in their offering affected individuals one year of free credit monitoring.

In some other breach cases, however, data is available to forensically determine with certainty what happened after a breach occurred, and sometimes long after a breach occurred. If this is the case, then the information existed when the breach actually occurred. The takeaway in those instances is that logs or other forensic data were not reviewed proactively to catch the breach sooner.  In a digital information world with bigger and bigger data hurtling down the road faster and faster, no one seems to be watching the gauges for trouble!

With the many tools available and the ease with which an employee can move data outside of an organization, a DLP solution is a necessity. Not only would your organization be able to watch sensitive information flowing into, throughout, and out of your network without impacting performance, you can lock down many of those outlets for data leakage. In addition to performing a HIPAA Risk Analysis and publishing policies and procedures, DLP can help your organization maintain compliance with regulations such as HIPAA, Red Flags Rule, PCI, and other state and Federal privacy regulations. As the costs for remediating a breach rise, DLP becomes a more prudent decision that can offer real value as well as peace of mind.

If you are interested in learning more about DLP or other related services, contact RISC Management and Consulting, LLC at 800.648.4358 or visit www.RISCsecurity.com.

 

References

http://news.sutterhealth.org/2015/09/11/sutter-health-informs-patients-of-unauthorized-document-handling-by-former-billing-unit-employee/

http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/

Cyber Security, Education, News Events, Trends & Technology, Upcoming Events

MFTC 2015 HIMSS Michigan Chapter Event

Welcome to the 9th Annual Midwest Fall Technology Conference – MFTC

After a successful 2014 conference at Chicago filled with learning, fun, and networking, we are happy to announce the Detroit Michigan HIMSS Chapter 2015 Event. Last year’s conference had close to 700 hundred attendees who participated in unique opportunities, enjoy authentic Chicago nightlife at the House of Blues and premier events.

2015 Midwest Fall Technology Conference
2015 Midwest Fall Technology Conference

To be held in:

Detroit, Michigan at the Detroit Marriot at the Renaissance Center

October 25th through the 27th

This Healthcare Information Technology (HIT) event will feature nationally recognized and regional speakers to address some of the most relevant and compelling topics of our time: innovation and leadership, analytics, health information exchanges, clinical engagement / patient engagement / mobile health and industry trends.

In addition to healthcare industry leaders, students and practioners will benefit from an amazing lineup of speakers, including local and national leaders in health information technology.  You will have an opportunity to discuss issues with colleagues from across the Midwest, to network, enjoy authentic Michigan landmarks, museums, nature, parks, nightlife and for your students to learn from industry veterans: http://www.michigan.org/hot-spots/detroit/

The Education tracks for the 2015 MFTC include:

Track A:  Strategy and Leadership

Track B:  Emerging Technology & Cybersecurity

Track C:  Public Policy (State and Federal)

Track D:  Innovation and Emerging Trends

Track E:  Clinical Informatics, Business Analytics & Research

For more Information please visit: http://michigan.himsschapter.org/Events/content.aspx?ItemNumber=41334

For registration please visit: http://www.midwest-ftc.org/

Our organization, RISC Management and Consulting, LLC is involved from a purely volunteer standpoint to assist in reaching Clinicians, Medical, Nursing professionals, educators, and students regarding this unique, local, and exceptional opportunity to learn and share.

Contact us to see how easy DLP can beRISC Data Loss Prevention Solution

800.648.4358 or Sales@RISCsecurity.com